CVE Database

57293+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-81395
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81394
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81393
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81392
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81391
5.5 MEDIUM

Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81390
5.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81387
5.5 MEDIUM

Exposure of sensitive system information to an unauthorized control sphere in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-81381
6.5 MEDIUM

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-81380
5.3 MEDIUM

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information …

Sep 8, 2026
CVE-2026-81377
6.5 MEDIUM

Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

Sep 8, 2026
CVE-2026-80091
6.5 MEDIUM

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80090
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80089
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80088
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80087
6.5 MEDIUM

Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80086
6.5 MEDIUM

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80084
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80082
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80079
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80078
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80076
6.5 MEDIUM

Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-80073
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-79904
5.0 MEDIUM

Photoshop Mobile is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature …

Sep 8, 2026
CVE-2026-78523
5.9 MEDIUM

Use after free in Windows DNS allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-78522
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78520
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Sep 8, 2026
CVE-2026-78516
4.3 MEDIUM

Buffer over-read in Windows Storage allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-78515
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78513
5.5 MEDIUM

Out-of-bounds read in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-78508
4.6 MEDIUM

Out-of-bounds read in Windows CD-ROM Driver allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-78506
5.5 MEDIUM

Improper null termination in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-78503
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78502
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78455
4.3 MEDIUM

Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-78454
5.5 MEDIUM

Out-of-bounds read in Windows CD-ROM Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-78453
6.5 MEDIUM

Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-78452
4.6 MEDIUM

Out-of-bounds read in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information with a physical attack.

Sep 8, 2026
CVE-2026-78451
6.8 MEDIUM

Untrusted pointer dereference in Microsoft Windows SCSI Class System File allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-78446
5.3 MEDIUM

Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-78441
6.5 MEDIUM

Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-77911
6.5 MEDIUM

Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-77896
6.5 MEDIUM

Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.

Sep 8, 2026
CVE-2026-77892
6.8 MEDIUM

No cwe for this issue in Windows Boot Manager allows an unauthorized attacker to elevate privileges with a physical attack.

Sep 8, 2026
CVE-2026-77891
6.4 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-77887
6.4 MEDIUM

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to execute code locally.

Sep 8, 2026
CVE-2026-77492
5.5 MEDIUM

Out-of-bounds read in Storage Port Driver allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-77491
5.5 MEDIUM

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-77488
5.5 MEDIUM

Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.

Sep 8, 2026
CVE-2026-73029
6.5 MEDIUM

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

Sep 8, 2026
CVE-2026-73019
4.3 MEDIUM

Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network.

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.